1. Go to www.google.com/mail/
This appears to be JSC issue because it doesn't reproduce on Chromium.
Can we get a crashtrace and platform?
Thread 0 Crashed: Dispatch queue: com.apple.main-thread
7 ??? 0x00003b3019e011e8 0 + 65077778584040
9 ??? 0x0000000106f357a0 0 + 4411578272
(In reply to comment #1)
> Can we get a crashtrace and platform?
Snow Leopard on MacPro.
Created attachment 103545 [details]
*** Bug 66011 has been marked as a duplicate of this bug. ***
Comment on attachment 103545 [details]
Clearing flags on attachment: 103545
Committed r92804: <http://trac.webkit.org/changeset/92804>
All reviewed patches have been landed. Closing bug.
*** Bug 66115 has been marked as a duplicate of this bug. ***
Is it not possible to write an automated regression test for this?
Seems like it should be possible. If possible, all checkins should come with a regression test.
(In reply to comment #10)
> Is it not possible to write an automated regression test for this?
As well, the bug only happens when three different register allocators in the system (the bytecompiler's virtual register allocator, the DFG parser's virtual register allocator, and the DFG back-end's physical register allocator) all make exactly the "wrong" decision based on the input. A test that would cause a failure just before this fix landed would be unlikely to continue to cause failures if even slight changes in register allocation were made subsequently.